Updating the firmware will not fix any of this. That is the sentence to carry away.

Ledger published three security bulletins on 27 August 2026: LSB 023, 024 and 025. Two concern the Ethereum app; the third is not about one app at all.

The one with the wider reach

LSB 023 describes a defect in the Ledger Secure SDK, the shared code every application compiles in. Per the bulletin, apps handle commands asynchronously, holding signing parameters in global state while a review screen waits, and the SDK did not stop the host sending another command in that interval — so each app had to reject one itself. An app that guarded every asynchronous entry point was safe; one that missed a single check left a window where parameters could be overwritten after the user read them, and the approval signed the new ones.

Exploiting it needs an adversary already controlling the device’s command exchange: a compromised wallet app, a hostile WebHID or WebUSB page, or host malware. Ledger reports no evidence of exploitation. Scope, per the bulletin: apps built against Secure SDK versions from August 2025 through v26.6.0, released 11 August 2026. The firmware is not affected.

The two Ethereum ones

LSB 024 — classified High, per Ledger’s published timeline — is an array-count truncation. A 16-bit element count was stored in an 8-bit field, so a list of 257 operations registered as 1; the device reviewed one entry, the signature covered the lot. It affects 1.19.0 through 1.22.2 and came from Felipe A. Manzano of Bitfinding via the bug bounty programme, with a variant reported independently by Florian Pradines through the same channel.

LSB 025, found by Ledger’s internal automated review, affects 1.20.0 through 1.22.2: the swap path checked a transaction’s address and quantity but not its nature, so a token approval could be signed in place of the payment, unseen. Both are fixed in 1.22.3, published 25 August; 1.22.2 was tagged without it.

The briefing

Open Ledger Live, update the apps, and read the version off the signer: Ledger states that firmware updates alone do not establish that affected apps have been replaced. For the Ethereum bugs the number is 1.22.3. LSB 023 has no single number: the correction reached apps through rebuilds against Secure SDK v26.6.1, re-published 21 August, so an older build lacks it.

None of this puts the recovery phrase at risk: the keys stay on the device. But a week thick with update notices is the weather phishing likes best. Nothing here needs your recovery phrase: not a bulletin, not an update prompt, not a support agent. It stays on paper or steel, off every keyboard and camera.

This is the trust-the-vendor question from our Ledger review, answered in public. A signer narrows your risk; it does not retire it, and crypto assets stay high-risk whatever version is installed — so read the bulletins, not our account of them.